PT-2023-19534 · WordPress+1 · Userpro
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UserPro plugin for WordPress versions through 5.1.1
Description
The UserPro plugin for WordPress through version 5.1.1 has a flaw that allows bypassing authentication through the
userpro fbconnect API endpoint. This bypass is achieved via the userpro fbconnect AJAX action.Recommendations
Update the UserPro plugin to a version later than 5.1.1.
Exploit
Correção
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Userpro